From 8cc06a87b951a6a1381b8cb9f5d51e9f37a2ae08 Mon Sep 17 00:00:00 2001 From: Piotr Buczek Date: Tue, 15 Sep 2020 12:03:32 +0200 Subject: [PATCH] Fixed XSS vulnerability in group picker --- src/components/GroupPicker.vue | 1 + 1 file changed, 1 insertion(+) diff --git a/src/components/GroupPicker.vue b/src/components/GroupPicker.vue index 6d75504..199531a 100644 --- a/src/components/GroupPicker.vue +++ b/src/components/GroupPicker.vue @@ -31,6 +31,7 @@ queryGroups({term, callback}) { this.$jira.getGroupsForPicker({query: term}).then(groupsResults => { + groupsResults.groups.map(group => group.name = group.html) callback({results: groupsResults.groups.map(group => this.mapGroupToGroupOption(group.name))}); }) },